Set roles and permissions for Superset Analytics
To manage the access to Superset dashboards and related components, use standard Control Tower roles and permissions. To view or change the Superset-related permissions in Control Tower, navigate to System setting > Role management.
On the page, the following roles are available with the default scope of permissions as detailed below:
- Admin users have full access with the ability to modify permissions of other roles.
- Developer users can do almost everything, except importing dashboards and changing permissions.
- Operator users have read-only permissions by default. It means they can only view dashboards but cannot modify or create them or their components.
For more information about the default permissions associated with the roles and instructions to change them, see Change access permissions in Control Tower.
Configure Keycloak roles
The above default Control Tower roles are configured and inherited from the wf-control-tower client in the WorkFusion's Keycloak-based user management system.
When a user logs in for the first time, Superset communicates with Keycloak. If the person is valid and matches Keycloak's access settings, he or she gets access to Superset dashboards and related analytics data. At that, the scope of their access depends on the permissions set for particular roles via Control Tower.
Change access permissions in Control Tower
Control Tower features the following permissions you can use to allow or restrict access to Analytics:
Analytics Read-only: enables you to view Superset-based dashboards and related data, subject to any access-restricting filters. However, users with only this permission cannot create or modify dashboards and their components.
Edit Dashboards: allows you to create and modify Superset-based dashboards, but not charts, datasets, or queries.
Edit Charts, Datasets & Queries: The permission allows you to create and modify components for Superset-based dashboards, such as charts, datasets, and queries.
Import Dashboards: allows you to import Superset-based dashboards as well as their components.
View Classic Dashboards: enables access to legacy Tableau-based dashboards.
For default permission setups associated with default roles, see the default permissions table. To change access permissions for a particular role, follow the instructions in the Manage Control Tower roles and permissions guide.
note
Changing Superset-related permissions is only available for the Admin role.
Fine-grain Superset access with filters
In Control Tower, you can create and apply filters to allow or restrict access to specific dashboards or analytics data for certain users or groups. With the filters, you can also flexibly change these access settings at runtime.
To access the filtering functionality, navigate to System Settings > Filters.

For instructions to create and assign a filter, refer to Set up filters for collaborative work.
The filtering functionality supports the following scenarios of how you can restrict or allow access to certain dashboards or analytics data.
Access to Business Process data
Using Filters, you can restrict or allow a specific user or group to access to the data pertaining to a Business Process. As a result, the user or group will not see the data related to the Business Process in the dashboard.

For more details on setting the type of access, refer to Implement role-based filtering on Business Process data.
Access to specific dashboards
You can also use Filters to limit access to specific dashboards for a particular user or group. As a result, the user or group will not have access to the dashboard.
To implement the scenario, create a filter, setting the Type to one of the following:
Dashboards to restrict access to specific dashboards.

Analytics Datasets to restrict access to specific data across dashboards.

Access to legacy Tableau dashboards
If you want to set filters for legacy Tableau-based dashboards, create a filter, setting the Type field to Dashboard Classic.
